Getting Data In

What are the capabilities of the Splunk Forwarder license?

FritzWittwer_ol
Contributor

We are running heavy forwarders to accept events from a number of universal forwarders, do some transforms and filtering with props and transforms, and then send them to our indexers.

We'd like to use the forwarder license on them, so we don't have to enable a connection to our license master. What capabilities are enabled with this license? Or more specific, are the functions of the parsing, merging and typing pipelines, according to HowIndexingWorks, available with the forwarding license?

0 Karma

vishaltaneja070
Motivator

Hello @FritzWittwer,

Forwarder license is already included in every splunk package which only allows data forwarding nothing else not even parsing.
The Forwarder license allows forwarding of unlimited data. Unlike a Free license, it enables authentication.

The Forwarder license is available only for instances that simply forward data. It is not valid for use on instances that also perform additional functions, such as indexing.

Forwarder licenses are included with Splunk. You do not need to purchase them separately.

There are several types of forwarders:

The universal forwarder has the Forwarder license applied automatically.
The light forwarder uses the Forwarder license, but you must manually enable it by changing to the Forwarder license group.
The heavy forwarder must also be manually converted to the Forwarder license group. If the heavy forwarder will also be performing indexing, the forwarder must instead have access to an Enterprise license.

Please see the below link:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/TypesofSplunklicenses

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...